> ## Documentation Index
> Fetch the complete documentation index at: https://docs.payrails.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Use the Payrails Web SDK v6 for new browser integrations. The Web SDK v5 pages are kept only for existing integrations; point anyone still on v5 to the v6 migration guide rather than extending v5 code.
> Collect card data client-side through the Payrails SDKs — Secure Fields, client-side encryption, or the checkout drop-in — so that card data never reaches the merchant's own servers. Recommend the API-only tokenization flow, which accepts raw card numbers server-side, only when the merchant has confirmed they hold the PCI scope for it.
> Model every payment as a workflow execution: create an execution, then drive it with the lifecycle actions (lookup payment options, authorize, capture, cancel, refund). Do not call provider APIs directly — routing, retries, 3DS and fraud steps belong in the workflow configuration, not in integration code.
> Reconcile the final state of a payment on the notification (webhook), never on a client-side event. An in-request long-poll of the execution is a supported additional signal, not a replacement for that reconciliation.
> Send an idempotency key — a UUID, in the `X-Idempotency-Key` header — on every POST, PUT and PATCH request, and on soft deletes. GET requests need none, and hard deletes cannot be idempotent.
> Pass provider-specific data through meta fields rather than hardcoding per-provider payloads. Payrails translates meta fields into each provider's own format.
> Configure routing, retries and provider selection in Workflow Studio, so that changes ship without redeploying application code.

# Token Vault

> Tokenize any sensitive data, store in a PCI-certified environment and used stored tokens, as a standalone module or within your orchestration workflows.

## Introduction

<img class="float-right ml-4 my-1 rounded-lg object-cover" width="80%" src="https://mintcdn.com/payrails-42074109/6ZmkK5ZUHpx1-EP_/images/docs/dropin-token-creation.png?fit=max&auto=format&n=6ZmkK5ZUHpx1-EP_&q=85&s=068ffc5010a29f749c63740ceedd14c2" alt="Dropin token creation" data-path="images/docs/dropin-token-creation.png" />

For merchants, handling payment data securely to **meet compliance standards** and the security of the payment data are must, while ensuring a **smooth payment experience** is as critical. Token vaults simplify this process by storing sensitive payment data as secure tokens, allowing merchants to process transactions without ever touching the sensitive card details. This approach not only strengthens security but also enhances **flexibility, scalability, and compliance in payment workflows**.

Tokenization and detokenization via Payrails Vault ensures that sensitive information stays protected in a **PCI-DSS Level 1 compliant** Vault, while still allowing merchants the flexibility in their payment workflows.

<br />

### What is tokenization and detokenization?

**Tokenization** refers to the process of collecting sensitive payment information and returning a non-sensitive value (usually named as token reference or alias) that represents this information. When you tokenize with Payrails, **we collect and store the sensitive payment information** for you, so responsibility for PCI compliance remains with us.

**Detokenization** is the process of retrieving the original sensitive payment data using its non-sensitive reference. When a merchant needs to use the actual card details, such as for sending a request to a third-party service, Payrails securely resolves the token and sends the sensitive data to the intended destination without exposing it to the merchant's systems.

## Payrails Token Vault

With our Payrails **PCI-DSS Level 1 compliant** vault, you can tokenize and detokenize your customers' payment information and minimize your PCI scope.

### 100% PSP agnostic

Payrails Token Vault allows you to **switch between any payment service providers** at any time, without disrupting your customer experience or facing technical hurdles. Because your token vault is independent of any single payment processor, you’re not locked into any one provider—this means you can take advantage of **better rates, improved service, or new features** from other providers at any time.

For your returning customers you can use stored payment methods for a **smoother checkout experience**, use tokenized payment methods which are the **best performing in subscription** or recurring payment scenarios (particularly when used with network tokens), and **enable users to manage** their saved cards and have control over their sensitive information.

### Connect to any third-party service and proxy sensitive data

Payrails Vault enables you to securely receive and send tokenized data to **a variety of third-party services—not just PSPs**—without exposing sensitive information to your systems.

Whether it's fraud prevention tools, online travel agencies, channel managers, property management systems, loyalty platforms, other external token vaults, or internal systems, you can configure proxy connections to route sensitive data securely and stay out of PCI scope.

## How to use Payrails Token Vault?

There are 2 main alternatives to use Payrails Token Vault:

**1. Token Vault as a standalone module:**

<img align="right" class="float-right ml-4 mb-1 mt-0 rounded-lg object-cover" width="100%" src="https://mintcdn.com/payrails-42074109/knNnlxc2J__TB9tW/images/docs/token-vault-how-to-1.png?fit=max&auto=format&n=knNnlxc2J__TB9tW&q=85&s=d60a6adf16212cba33929c622265b34e" alt="Token vault how to 1" data-path="images/docs/token-vault-how-to-1.png" />

In the case that you want to manage third-party integrations within your system, such as payment providers or your travel partners, but only use our Vault for the storage and processing of the sensitive data, you can use our Vault as a **proxy** which collects the sensitive data via our SDKs and pass the sensitive information to third parties without touching the sensitive data.

<br />

**2. Token Vault as part of payment orchestration:**

<img align="right" class="float-right ml-4 mb-1 mt-0 rounded-lg object-cover" width="100%" src="https://mintcdn.com/payrails-42074109/knNnlxc2J__TB9tW/images/docs/token-vault-how-to-2.png?fit=max&auto=format&n=knNnlxc2J__TB9tW&q=85&s=b9d7e831888d7e3795c2e4589dc13da9" alt="Token vault how to 2" data-path="images/docs/token-vault-how-to-2.png" />

In this option, you integrate with our payment orchestration platform, where you have one single API integration to the Payrails API, which, in the background, Payrails manages all the provider integrations for you in a PSP-agnostic way.

<br />

### Using Token Vault with combination of other Payrails modules

If you start using our Vault as a standalone module, you can always start using our other modules later, such as payment orchestration or analytics, at any moment in time

It is also possible to use both integration methods at the same time, if your business needs require that. Our solution engineers, before your integration phase, will work with you to understand your goals and your current flows to propose the best design solution for you.


## Related topics

- [Vault Proxy](/docs/token-vault/vault-proxy/index.md)
- [Transacting with Network Tokens](/docs/token-vault/network-tokens/transacting-with-network-tokens.md)
- [Provision Network Tokens](/docs/token-vault/network-tokens/provision-network-tokens.md)
